Desktop OIDC: non-blocking fetch + poll, don't leave webview
Some checks failed
ci / build-test (push) Has been cancelled
ci / docker-build (push) Has been cancelled
Desktop App / Build Linux (amd64) (push) Has been cancelled
Desktop App / Attach to Release (push) Has been cancelled

SPA fetches /oidc/open (returns session ID immediately), then polls
/oidc/result every 500ms. Go server opens browser in a goroutine.
Webview never leaves the Wails origin. Token is saved to keychain and
returned through the poll response.
This commit is contained in:
2026-07-14 00:09:46 +02:00
parent c8ef3793d7
commit 8b3fe02a10
4 changed files with 99 additions and 62 deletions

View File

@@ -72,11 +72,43 @@
try {
await startLogin()
} catch (e: any) {
error = e.message || 'OIDC login failed'
const msg = e?.message || e || ''
if (msg.startsWith('DESKTOP_OIDC:')) {
const url = msg.substring('DESKTOP_OIDC:'.length)
await desktopOIDC(url)
return
}
error = msg || 'OIDC login failed'
oidcLoggingIn = false
}
}
async function desktopOIDC(apiUrl: string) {
try {
const resp = await fetch(`http://127.0.0.1:18901/oidc/open?apiUrl=${encodeURIComponent(apiUrl)}`)
const { id } = await resp.json()
if (!id) throw new Error('No session ID')
for (let i = 0; i < 600; i++) {
await new Promise(r => setTimeout(r, 500))
const r = await fetch(`http://127.0.0.1:18901/oidc/result?id=${id}`)
const data = await r.json()
if (data.token) {
setConfig({ apiUrl, token: data.token, isDesktop: true })
initConfig({ apiUrl, token: data.token, isDesktop: true })
oidcLoggingIn = false
onConnected()
return
}
if (!data.pending || data.pending === 'false') break
}
error = 'Login timed out'
} catch (e: any) {
error = e?.message || 'Could not reach login service'
}
oidcLoggingIn = false
}
function logoutOIDC() {
oidcLogout()
oidcUser = null